How does npm differ from any other package manager in that sense?
They typically don't execute arbitrary code when setting up the project.
They typically don't execute arbitrary code when setting up the project.